CVE-2015-3224
MEDIUM 4.3EPSS 44.7%
request.rb in Web Console before 2.1.3, as used with Ruby on Rails 3.x and 4.x, does not properly restrict the use of X-Forwarded-For headers in determining a client's IP address, which allows remote attackers to bypass the whitelisted_ips protection mechanism via a crafted request.
- CVSS v2.0
- 4.3 MEDIUM
AV:N/AC:M/Au:N/C:N/I:P/A:N - EPSS
- 44.71% chance of exploitation in the next 30 days, 99th percentile
- Nuclei
- medium · CWE-284
- Published
- 2015-07-26
- Updated
- 2024-08-06
Proof-of-concept exploits (7)
- 0x00-0x00/CVE-2015-32242★ · 2018-02-08
- 0xEval/cve-2015-32246★ · 2018-05-03
- Sic4rio/CVE-2015-32240★ · 2025-07-06
- n000xy/CVE-2015-3224-0★ · 2021-02-27
- redirected/tricks0★ · 2018-08-17
- xda3m00n/CVE-2015-3224-0★ · 2021-02-27
- SQU4NCH/CVE-2015-3224